Debian Package Tracker
Register | Log in
Subscribe

libprotocol-http2-perl

HTTP/2 protocol implementation with client and server libraries

Choose email to subscribe with

general
  • source: libprotocol-http2-perl (main)
  • version: 1.12-2
  • maintainer: Debian Perl Group (archive) (DMD) (LowNMU)
  • uploaders: gregor herrmann [DMD]
  • arch: all
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.10-1
  • oldstable: 1.10-2
  • stable: 1.11-1
  • testing: 1.12-1
  • unstable: 1.12-2
versioned links
  • 1.10-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.10-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.11-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.12-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.12-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libprotocol-http2-perl
action needed
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2026-10725: Protocol::HTTP2 versions through 1.12 for Perl is vulnerable to a HTTP/2 Bomb. Protocol::HTTP2's inbound HPACK path has no header-list size limit, so a small HTTP/2 request can expand into large server memory (the "HTTP/2 bomb"). The headers_decode method materialises a full key+value copy per indexed reference with no running size check, and the stream_header_block_add method appends (since version 1.12) every CONTINUATION frame to the per-stream buffer unbounded. MAX_HEADER_LIST_SIZE (default 65536) is advertised in SETTINGS but never consulted on decode. It is absent from the decoder and from the :limits export tag.
Created: 2026-06-06 Last update: 2026-06-07 07:30
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-10725: Protocol::HTTP2 versions through 1.12 for Perl is vulnerable to a HTTP/2 Bomb. Protocol::HTTP2's inbound HPACK path has no header-list size limit, so a small HTTP/2 request can expand into large server memory (the "HTTP/2 bomb"). The headers_decode method materialises a full key+value copy per indexed reference with no running size check, and the stream_header_block_add method appends (since version 1.12) every CONTINUATION frame to the per-stream buffer unbounded. MAX_HEADER_LIST_SIZE (default 65536) is advertised in SETTINGS but never consulted on decode. It is absent from the decoder and from the :limits export tag.
Created: 2026-06-06 Last update: 2026-06-07 07:30
1 security issue in bullseye high

There is 1 open security issue in bullseye.

1 important issue:
  • CVE-2026-10725: Protocol::HTTP2 versions through 1.12 for Perl is vulnerable to a HTTP/2 Bomb. Protocol::HTTP2's inbound HPACK path has no header-list size limit, so a small HTTP/2 request can expand into large server memory (the "HTTP/2 bomb"). The headers_decode method materialises a full key+value copy per indexed reference with no running size check, and the stream_header_block_add method appends (since version 1.12) every CONTINUATION frame to the per-stream buffer unbounded. MAX_HEADER_LIST_SIZE (default 65536) is advertised in SETTINGS but never consulted on decode. It is absent from the decoder and from the :limits export tag.
Created: 2026-06-06 Last update: 2026-06-07 07:30
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2026-10725: Protocol::HTTP2 versions through 1.12 for Perl is vulnerable to a HTTP/2 Bomb. Protocol::HTTP2's inbound HPACK path has no header-list size limit, so a small HTTP/2 request can expand into large server memory (the "HTTP/2 bomb"). The headers_decode method materialises a full key+value copy per indexed reference with no running size check, and the stream_header_block_add method appends (since version 1.12) every CONTINUATION frame to the per-stream buffer unbounded. MAX_HEADER_LIST_SIZE (default 65536) is advertised in SETTINGS but never consulted on decode. It is absent from the decoder and from the :limits export tag.
Created: 2026-06-06 Last update: 2026-06-07 07:30
debian/patches: 1 patch to forward upstream low

Among the 1 debian patch available in version 1.12-2 of the package, we noticed the following issues:

  • 1 patch where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2026-06-06 Last update: 2026-06-06 23:00
testing migrations
  • excuses:
    • Migration status for libprotocol-http2-perl (1.12-1 to 1.12-2): Waiting for test results or another package, or too young (no action required now - check later)
    • Issues preventing migration:
    • ∙ ∙ Autopkgtest for apache2/2.4.67-1: amd64: Pass, arm64: Pass, i386: Pass, loong64: Test triggered, ppc64el: Pass, riscv64: Pass, s390x: Pass
    • ∙ ∙ Autopkgtest for libprotocol-http2-perl/1.12-2: amd64: Pass, arm64: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, riscv64: Pass, s390x: Pass
    • ∙ ∙ Too young, only 2 of 5 days old
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/libp/libprotocol-http2-perl.html
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • Not considered
news
[rss feed]
  • [2026-06-06] Accepted libprotocol-http2-perl 1.12-2 (source) into unstable (gregor herrmann)
  • [2026-02-24] libprotocol-http2-perl 1.12-1 MIGRATED to testing (Debian testing watch)
  • [2026-02-20] Accepted libprotocol-http2-perl 1.12-1 (source) into unstable (gregor herrmann)
  • [2024-05-25] libprotocol-http2-perl 1.11-1 MIGRATED to testing (Debian testing watch)
  • [2024-05-22] Accepted libprotocol-http2-perl 1.11-1 (source) into unstable (gregor herrmann)
  • [2023-07-30] libprotocol-http2-perl 1.10-3 MIGRATED to testing (Debian testing watch)
  • [2023-07-28] Accepted libprotocol-http2-perl 1.10-3 (source) into unstable (gregor herrmann)
  • [2022-12-07] libprotocol-http2-perl 1.10-2 MIGRATED to testing (Debian testing watch)
  • [2022-12-04] Accepted libprotocol-http2-perl 1.10-2 (source) into unstable (Jelmer Vernooij) (signed by: Jelmer Vernooij)
  • [2019-11-26] libprotocol-http2-perl 1.10-1 MIGRATED to testing (Debian testing watch)
  • [2019-11-23] Accepted libprotocol-http2-perl 1.10-1 (source) into unstable (gregor herrmann)
  • [2018-08-09] libprotocol-http2-perl 1.09-1 MIGRATED to testing (Debian testing watch)
  • [2018-08-06] Accepted libprotocol-http2-perl 1.09-1 (source) into unstable (gregor herrmann)
  • [2017-06-20] libprotocol-http2-perl 1.08-1 MIGRATED to testing (Debian testing watch)
  • [2017-02-10] Accepted libprotocol-http2-perl 1.08-1 (source all) into unstable, unstable (gregor herrmann)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.11-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing